Bài viết

AI-Enhanced SQL Injection Detection Framework: A Novel Approach Combines LLMs with Traditional Fuzzing to Improve Web Application Vulnerability Detection

Từ khóaSQL Injectiontrí tuệ nhân tạoan toàn webkiểm thử xâm nhậpmô hình ngôn ngữ lớnphần mở rộng burp suite

Tóm tắt

 Tấn công SQL injection ảnh hưởng đến khoảng 65% ứng dụng web, trong khi các công cụ truyền thống thường bỏ sót các lỗ hổng phụ thuộc ngữ cảnh. Chúng tôi đề xuất AESIDF(AI-Enhanced SQLi Detection Framework), một khung lai kết hợp Mô hình ngôn ngữ lớn (LLM) với kỹ thuật fuzzing song song nhằm phân tích lỗ hổng theo ngữ nghĩa. Được đánh giá trên 26 kịch bản benchmark từ PortSwigger, DVWA(Damn Vulnerable Web Application) và OWASP(Open Web Application Security Project) Juice Shop, phương pháp của chúng tôi đạt tỷ lệ phát hiện 92,3% so với 76,9% của SQLMap, đồng thời giảm khoảng 68,8% số lượng request. Các kết quả sơ bộ này cho thấy khả năng suy luận ngữ cảnh của LLM(Large Language Model) có thể cải thiện kiểm thử bảo mật tự động; tuy nhiên, cần xác thực rộng hơn trên các tập dữ liệu lớn và đa dạng hơn để khẳng định khả năng tổng quát hóa.

Lượt tải theo tháng

0234512/2501/2602/2603/2604/2605/26

Di chuột vào cột để xem số lượt tải.

Cách trích dẫn

Nguyễn Lê Quốc Đạt, Nguyễn Lê Quốc Anh, Nguyễn Mạnh Thắng (2025). AI-Enhanced SQL Injection Detection Framework: A Novel Approach Combines LLMs with Traditional Fuzzing to Improve Web Application Vulnerability Detection. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 3(26), 70-78. https://doi.org/10.54654/isj.v3i26.1179

Tài liệu tham khảo

  1. 1.OWASP Foundation, “OWASP Top 10 - 2021: The Ten Most Critical Web Application Security Risks” (2021). Access time: 12/01/2024, https://owasp.org/Top10/.
  2. 2.S. Saiyed, H. Sharma, and V. Kumar, “Static analysis approach for SQL injection vulnerability detection,” Journal of Information Security and Applications, vol. 45, pp. 1–12, 2019.
  3. 3.W. G. J. Halfond and A. Orso, “AMNESIA: Analysis and monitoring for neutralizing SQL-injection attacks,” ACM Transactions on Software Engineering, vol. 34, no. 5, pp. 1–52, 2008.
  4. 4.D. Appelt, C. D. Nguyen, L. C. Briand, and N. Alshahwan, “Automated testing for SQL injection vulnerabilities: An input mutation approach,” in Proc. Int. Symp. Software Testing and Analysis (ISSTA), San Jose, CA, USA, Jul. 2014, pp. 259–269.
  5. 5.Y. Tang, S. Chen, and L. Wang, “SQL injection detection using convolutional neural networks,” IEEE Access, vol. 8, pp. 132505–132517, 2020.
  6. 6.T. Brown et al., “Language models are few-shot learners,” in Proc. NeurIPS, 2020, pp. 1877–1901.
  7. 7.Y. Jiang et al., “When Fuzzing Meets LLMs: Challenges and Opportunities,” in Proc. ACM CCS, Salt Lake City, USA, 2024, pp. 1–15.
  8. 8.H. X. Dau, N. T. T. Trang, and N. T. Hung, “A Survey of Tools and Techniques for Web Attack Detection,” Journal of Science and Technology on Information Security, Special Issue CS, no. 15, pp. 109–130, 2022. DOI: doi.org/10.54654/isj.v1iCS(15).403.
  9. 9.N. M. Thien, P. D. Khoa, N. D. Vuong, and N. V. Hung, “AI application framework for automatic vulnerabilities exploit,” Journal of Science and Technology on Information Security, vol. 1, no. 13, pp. 80–92, 2022. DOI: doi.org/10.54654/isj.v1i13.234.
  10. 10.T. P. Ho, H. T. Nam, and N. M. Thang, “A new approach to improving web application firewall performance based on support vector machine method with analysis of HTTP request,” Journal of Science and Technology on Information Security, vol. 1, no. 15, pp. 62–73, 2022. DOI: doi.org/10.54654/isj.v1i15.391

Bài viết liên quan

AI-Enhanced SQL Injection Detection Framework: A Novel Approach Combines LLMs with Traditional Fuzzing to Improve Web Application Vulnerability Detection | Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin